Skip to content

Prevent invalid year input - #7440

Open
bahman026 wants to merge 10 commits into
nextcloud:mainfrom
bahman026:prevent-invalid-year-input
Open

bahman026 wants to merge 10 commits into
nextcloud:mainfrom
bahman026:prevent-invalid-year-input

Conversation

@bahman026

@bahman026 bahman026 commented Dec 8, 2025 •

Copy link
Copy Markdown
  • Target version: main

Summary

This PR fixes an issue where a user can manually enter an invalid year in the due date input (for example: 20250).
Although the UI displays a date picker, users can still type values directly into the datetime-local field. When an invalid 5-digit year is submitted, it is saved in the database without validation.

After refreshing the page, PHP throws an error such as:

Failed to parse time string (20250-12-09 04:30:00) at position 12 (0):
Double time specification

Before:
Because of this invalid date, the card cannot be edited or updated again until the entire board is deleted.

screen-capture.mp4

After:

capture.mp4

Checklist

  • Code is properly formatted
  • Sign-off message is added to all commits
  • Documentation (manuals or wiki) has been updated or is not required

@bahman026
bahman026 force-pushed the prevent-invalid-year-input branch 4 times, most recently from a39498a to d4898e5 Compare December 9, 2025 14:31
@rakekniven
rakekniven force-pushed the prevent-invalid-year-input branch from bbb003d to 1c77d11 Compare December 20, 2025 10:50
@github-actions

Copy link
Copy Markdown
Contributor

Hello there,
Thank you so much for taking the time and effort to create a pull request to our Nextcloud project.

We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process.

Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6

Thank you for contributing to Nextcloud and we hope to hear from you soon!

(If you believe you should not receive this message, you can add yourself to the blocklist.)

@bahman026
bahman026 force-pushed the prevent-invalid-year-input branch from f1367fc to 72c807d Compare May 18, 2026 09:13
@bahman026 bahman026 closed this May 18, 2026
@bahman026
bahman026 force-pushed the prevent-invalid-year-input branch from 72c807d to 7986cfb Compare May 18, 2026 09:17
@bahman026 bahman026 reopened this May 18, 2026
@bahman026
bahman026 force-pushed the prevent-invalid-year-input branch 4 times, most recently from 3fa2f80 to 08157ee Compare May 18, 2026 10:10
@bahman026
bahman026 requested a review from luka-nextcloud May 18, 2026 10:11
bahman026 added 4 commits May 31, 2026 10:27
Signed-off-by: Bahman Jafarzadeh <bahman026@gmail.com>
Signed-off-by: Bahman Jafarzadeh <bahman026@gmail.com>
Signed-off-by: Bahman Jafarzadeh <bahman026@gmail.com>
Signed-off-by: Bahman Jafarzadeh <bahman026@gmail.com>
@bahman026
bahman026 force-pushed the prevent-invalid-year-input branch from 08157ee to 9be1702 Compare May 31, 2026 07:04
bahman026 and others added 5 commits May 31, 2026 10:41
Signed-off-by: bahman <42313073+bahman026@users.noreply.github.com>
The 'date' rule only accepted two of the formats that the API actually
receives, and relied on \DateTime to reject the rest. \DateTime silently
misreads out of range input instead of failing: '12345-01-01' is parsed as
2005-01-01 12:34. Such a value is written to the DATETIME column but can no
longer be read back, which leaves the card permanently broken.

Match the value against an explicit list of accepted formats and reject
overflowing components (month 13, February 30), which createFromFormat()
only reports through its warnings. An empty value stays valid so optional
dates can be unset.

Validate startdate the same way as duedate, and check both of them on
create() as well - previously only update() checked duedate, so an invalid
date could still enter the database through card creation.

On the frontend, bound the native datetime-local input on both ends instead
of only the upper one, so a year like 20250 can no longer be typed.

Signed-off-by: bahman026 <bahman026@gmail.com>
…r-input

# Conflicts:
#	lib/Service/CardService.php
The start date ends up in the same DATETIME column as the due date and is
now validated the same way server side, so the picker needs the same range.
Without it a year like 20250 is still accepted by the input and only
rejected once the request reaches the validator.

Move the two bounds into a shared helper rather than repeating them in both
selectors.

Signed-off-by: bahman026 <bahman026@gmail.com>
createFromFormat() does not bound 'Y' to four digits - it consumes as many
digits as it finds, so '12345-01-01' and '20250-12-09 04:30:00' parse
cleanly and produce no warnings, and the format list alone let them through.

Compare the parsed year against the range the DATETIME column can hold,
which is also the range the date pickers now offer.

Signed-off-by: bahman026 <bahman026@gmail.com>
@bahman026

bahman026 commented Sep 28, 2026 •

Copy link
Copy Markdown
Author

Hi @luka-nextcloud,

Following your approval, I’ve extended the fix with a few additional validations:

  • duedate and startdate are now validated on both create and update.
  • Dates with years outside the supported DATETIME range (e.g. 20250) and invalid dates such as month 13 are rejected.
  • The startdate picker now uses the same date boundaries as the duedate picker.
  • Added unit tests covering the new validation cases in CardServiceValidatorTest.

The latest commits are currently waiting for CI approval. Could you please approve the workflow runs and review the updated changes when you have a chance?

Thank you.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants